APP: Cisco Unity Express RMI Insecure Deserialization Remote Code Execution

This signature detects attempts to exploit a known vulnerability Cisco Unity Express. A successful attack can lead to arbitrary code execution.

Extended Description

A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a malicious serialized Java object to the listening Java Remote Method Invocation (RMI) service. A successful exploit could allow the attacker to execute arbitrary commands on the device with root privileges.

Affected Products

Cisco unity_express

Short Name
APP:REMOTE:CVE-2018-15381-RCE
Severity
Major
Recommended
True
Recommended Action
Drop
Category
APP
Keywords
CVE-2018-15381 Cisco Code Deserialization Execution Express Insecure RMI Remote Unity bid:105876
Release Date
01/10/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
Port
TCP/1099
False Positive
Unknown
Vendors

Cisco

CVSS Score

10.0

Found a potential security threat?